sted Posted September 27, 2013 Posted September 27, 2013 a lot of my schools (read probably all) are moving to office 365 as lln are going away . Now i quickly set it up in one school (they wanted email addresses asap so i just dumped ad users into a spreadsheet twiddle a bit and uploaded them so they now all have shiny new office 265 email). In the future (or possibly retroactively bearing in mind as usernames are in that schoo, staffab and office 365 are first.surname (and to complicate further a few have married name on 365 not in ad)) how easy and more importantly useful is it to set up sso? If its a lot of faffing round to just skip 1 password is it worth it?
zag Posted September 27, 2013 Posted September 27, 2013 Pointless imo, our students and staff have no problem logging on to webmail when they need to. Outlook client requires no login after the first setup. Simples
sted Posted September 27, 2013 Author Posted September 27, 2013 Pointless imo, our students and staff have no problem logging on to webmail when they need to. Outlook client requires no login after the first setup. Simples thats my take on it as well just wanted opinions looking into sso it looks like a right pita
hallb15 Posted September 27, 2013 Posted September 27, 2013 We are going down the Office365 route as well. I saw the SSO option, but haven't decided as yet. From a security point of view, we all know what certain members of staff can be like when it comes to leaving themselves logged in to a computer and walking away...
sted Posted September 27, 2013 Author Posted September 27, 2013 We are going down the Office365 route as well. I saw the SSO option, but haven't decided as yet. From a security point of view, we all know what certain members of staff can be like when it comes to leaving themselves logged in to a computer and walking away... stupidity/lazyness will always trump technology
hallb15 Posted September 27, 2013 Posted September 27, 2013 This leads me on to another issue. One domain or two? As all LLN schools were originally configured with two domains, one for Admin and one for Curriculum, and have a CISCO router to separate them, (which I assume LLN will want back) what are you doing about your domains when you leave LLN?
sted Posted September 27, 2013 Author Posted September 27, 2013 (edited) This leads me on to another issue. One domain or two? As all LLN schools were originally configured with two domains, one for Admin and one for Curriculum, and have a CISCO router to separate them, (which I assume LLN will want back) what are you doing about your domains when you leave LLN? i have as admin servers get replaced been moving them to a single network anyway just leaving a 2nd nic in the "admin" server for avco all thats all that half of the router does (unless they have voip) school im at now has had a single domain for a few years im moving another to single domain at half term (admin server and 2-3 pcs wow that needs a domain lol) they even had a better spec dell server lying unused than their ye olde admin hp server Edited September 27, 2013 by sted
Norphy Posted September 27, 2013 Posted September 27, 2013 thats my take on it as well just wanted opinions looking into sso it looks like a right pita I did it in an afternoon. It's not that hard. The instructions that Microsoft provide on their website are pretty clear and comprehensive and will guide you through the process nicely. It means that your users will have to remember one less password which is always useful. Plus once ADFS is set up, there's no reason why you couldn't use it for other services. We have it authenticating our Blackboard users and we're using a hosted service from them now.
sted Posted September 27, 2013 Author Posted September 27, 2013 I did it in an afternoon. It's not that hard. The instructions that Microsoft provide on their website are pretty clear and comprehensive and will guide you through the process nicely. It means that your users will have to remember one less password which is always useful. Plus once ADFS is set up, there's no reason why you couldn't use it for other services. We have it authenticating our Blackboard users and we're using a hosted service from them now. ok then do i need any extra hardware/ looking at it its the certificates stuff that puts me off and my domain is school.local and email is now longschoolname.co.uk iirc
Norphy Posted September 27, 2013 Posted September 27, 2013 Depends. I have it running on VMs so I didn't need any additional hardware. You could put it on existing member servers if you wanted to. You can't put the ADFS and ADFS proxy on the same box, you shouldn't out either onto a domain controller. The only certificate that you need to worry about is the one that your ADFS server is published at. It will need to be a trusted cert from the likes of Verisign or Comodo (I got ours from Janet). It doesn't matter what your email domain or AD domain is called. You will need to have the ADFS proxy on a publicly accessible IP address though, that may be your biggest difficulty. I don't know if it will work through a reverse proxy or not.
xenonive Posted September 27, 2013 Posted September 27, 2013 You might want to consider using a mesh host, like Welcome to YouID they can sync all your usernames and passwords over various services for single sign on . Think its about £2 per user but they can host a frontend for users
timbo343 Posted September 27, 2013 Posted September 27, 2013 We have Office365 for students and it has crossed my mind a couple of times if we offer SSO but the negs outweigh the positives, such as they are relaying on us to authenticate for them. What happens if i want to do work on the servers over the weekend and restart the servers, students are then left without access to their emails.
sted Posted September 27, 2013 Author Posted September 27, 2013 Depends. I have it running on VMs so I didn't need any additional hardware. You could put it on existing member servers if you wanted to. You can't put the ADFS and ADFS proxy on the same box, you shouldn't out either onto a domain controller. The only certificate that you need to worry about is the one that your ADFS server is published at. It will need to be a trusted cert from the likes of Verisign or Comodo (I got ours from Janet). It doesn't matter what your email domain or AD domain is called. You will need to have the ADFS proxy on a publicly accessible IP address though, that may be your biggest difficulty. I don't know if it will work through a reverse proxy or not. i have a single external ip address but thats atm used for my bodged set up to test then went live) terminal server but i could probably redirect the ports to the requisite server i have s 2008r1 box there doing jack (was the main server went wyrd was replaced now im trying to rehabilitate it as extra backup storage)
Norphy Posted September 27, 2013 Posted September 27, 2013 Do you have control of your external DNS as well?
sted Posted September 27, 2013 Author Posted September 27, 2013 Do you have control of your external DNS as well? personally no but i "think" the boss does as he sorted the mx records out but atm i doubt the url does owt its just for email
funkyfin2000 Posted September 30, 2013 Posted September 30, 2013 Worth considering RM Unify for Single Sign On as well driven by your AD - gives you single sign on to tons of other Educational Cloud services - Discover: RM Unify Dirt cheap as well for the functionality it gives!
Cache Posted September 30, 2013 Posted September 30, 2013 I do quite like the solution of DirSync with Password Sync, it's removed a lot of the "I can't remember my password because it's different from the computer" arguements we used to have and staff are being a bit more receptive to it. It's also the setup we dived straight in with on filtered OU's after the initial testing was complete and was very easy to go with. The only thing some users don't particularly like is typing the whole email address in rather then just their username, however that is the least of my worries and not a fantastic reason to look at the SSO/ADFS route at the moment.
jamesbmarshall Posted October 14, 2013 Posted October 14, 2013 how easy and more importantly useful is it to set up sso? Back to the OP's original question, I've finally got around to writing up my thoughts on this topic. It's taken me a while, and it's a bit of a read, but: Deploying Office 365 Education? You don't need single sign-on, and here's why! 2
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now